Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Deliberately create slow SSH response? |
|---|---|
| Date: | Wed, 9 Jul 2008 11:25:49 -0700 |
On Jul 9, 2008, at 9:55 AM, Zembower, Kevin wrote:
This might seem like a strange question to ask, but is there a way to
deliberately create a slow response to an SSH request? I'm annoyed at
the large number of distributed SSH brute-force attacks on a server I
administer, trying to guess the password for 'root' and other accounts.
I think that my server is pretty secure; doesn't allow root to log in
through SSH, only a restricted number of accounts are allowed SSH
access, with I think pretty good passwords. But still, the attempts
annoy me.
I think the best place to do that is in PAM. Here's a module: http://www-uxsup.csx.cam.ac.uk/~pjb1008/project/pam_delay/pam_delay/pam_delay.html
-b
smime.p7s
Description: S/MIME cryptographic signature
| Previous by Date: | problems with ChrootDirectory, Joseph Spenner |
|---|---|
| Next by Date: | Re: Deliberately create slow SSH response?, H. Kurth Bemis |
| Previous by Thread: | RE: Deliberately create slow SSH response?, Michael G. Reed |
| Next by Thread: | Re: Deliberately create slow SSH response?, H. Kurth Bemis |
| Indexes: | [Date] [Thread] [Top] [All Lists] |